fix(vds-nftables): open port 8443 — 3x-ui Xray REALITY inbound

Previous T3 fix missed port 8443. In modules/containers/3x-ui.nix,
the 3x-ui container's Xray REALITY inbound is mapped directly
to host port 8443:

  basePorts = [
    '127.0.0.1:2049:2049/tcp'  # panel
    '127.0.0.1:2096:2096/tcp'  # subscription
    '0.0.0.0:8443:8443/tcp'     # Xray REALITY inbound
  ];

This is a DIRECT public mapping (0.0.0.0, not localhost), not
proxied through nginx. The 'reality443Forwarding' option
(погашен в T10) was a separate mechanism that forwarded host:443
→ 127.0.0.1:15380 → container:443 via nginx stream.

After T10, the nginx stream is removed. Xray is now ONLY on
host port 8443 (direct mapping). Port 443 in the nftables
ruleset is still open but not used by Xray — it was only used
through the stream mechanism (now removed).

Owner confirmation 2026-10-10: 'нужен 8443 порт для 3x-ui inbound'.

Fix: add 'tcp dport 8443 accept' to the nftables ruleset.
Xray REALITY is now reachable on:
  - 8443 (direct, always was the primary)
  - 443 (only if nginx vhost proxies to container, not the case here)
This commit is contained in:
2026-10-10 17:19:33 +03:00
parent 2649e2fbcc
commit 51ea19aef4
+7
View File
@@ -128,6 +128,13 @@
# Xray REALITY inbound (treca acts as relay from sapphira via XHTTP)
tcp dport 443 accept
# 3x-ui Xray REALITY inbound on container (0.0.0.0:8443:8443 in
# modules/containers/3x-ui.nix). Direct public mapping — NOT
# proxied through nginx (that was `reality443Forwarding`,
# погашен в T10). ADDED 2026-10-10: previous T3 fix missed
# this port, Xray was unreachable from outside.
tcp dport 8443 accept
# log for diagnostics (journalctl -k | grep nft-drop)
log prefix "nft-drop: " flags all counter drop
}